boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Wednesday, July 29, 2026 · all times UTC← 2026-07-28 · archive · 2026-07-30 →

Security Box Score — July 29, 2026

274 CVEs published, led by Apache Software Foundation (41).

274 CVEs published July 29, 2026: 47 critical, 116 high, 103 medium, 8 low; 1 in the KEV catalog at press time; 5 with a public exploit reference; 0 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 249 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published891621319——
KEV catalog size1675

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

920 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux8342314207123163711120.17.8.0016+321 ▲
microsoft664142110598132114286241.77.8.0047+444 ▲
google1211386157634556397760.47.8.0025-587 ▼
red hat1333551614017524200.06.5.0030+18 ▲
apple167271577813338872.66.5.0027+115 ▲
canonical72738115000.05.6.0014+1 ▲
suse82141241000.08.5.0039+2 ▲
freebsd01601240000.07.8.0016-9 ▼
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco1638818120561231.67.5.0057+6 ▲
ubiquiti2536142110338.38.8.0049+17 ▲
palo alto networks1425131471328.04.7.0028+5 ▲
fortinet14236611028626.17.2.0040+12 ▲
netgear62300221000.04.6.0024-11 ▼
f58165830416.38.6.0057+2 ▲
vmware8121821718.38.2.0039+5 ▲
checkpoint31236303216.77.7.04550
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache16532063139106113310.37.5.0054+54 ▲
mozilla711275142340900.08.1.0031+22 ▲
drupal465165355412.05.9.0026+46 ▲
gitlab205107377423.94.9.0029-4 ▼
github6121380000.06.0.0042+5 ▲
docker070520000.08.2.0016-4 ▼
wordpress3311102266.78.6.7979+3 ▲
kubernetes110001000.02.4.0035+1 ▲
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle11091379343653322612730.28.1.0036+867 ▲
adobe1052492611410541931.27.8.0026-27 ▼
ibm701945969660600.07.5.0034+38 ▲
progress334262970600.08.0.0038+28 ▲
solarwinds15221633010418.29.1.0058+12 ▲
zohocorp362220000.07.8.0146+2 ▲
veeam152300100.08.6.00510
atlassian3303001300.08.0.0026+3 ▲
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
rockwell automation172441820000.08.7.0029+10 ▲
synology02325133000.05.6.0025-5 ▼
d-link8200596300.05.5.0105-2 ▼
siemens7161870000.07.6.00240
schneider electric391620000.08.6.0037-3 ▼
abb170430000.07.2.0018-5 ▼
hikvision550320000.07.2.0038+5 ▲
moxa050320000.07.0.0029-5 ▼
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
sourcecodester49120006258000.05.5.00340
openclaw441110583914000.07.0.0026-17 ▼
dell4399547443211.07.1.0021+5 ▲
capgo2283242381000.07.1.0037-24 ▼
nvidia43821254160000.07.8.0037+37 ▲
imagemagick3576155812000.05.3.00180
spring073231391000.06.5.0024-72 ▼
itsourcecode1871001952000.02.1.0033-25 ▼

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-63030.977999.99.8
CVE-2026-16232.891299.89.3
CVE-2026-50522.846199.79.8
CVE-2026-15409.836699.710.0
CVE-2026-60137.797999.65.9
CVE-2026-6875.775899.59.5
CVE-2026-25089.761199.59.8
CVE-2026-45659.760899.58.8
CVE-2026-0770.634299.19.8
CVE-2026-48282.423998.610.0
Highest CVSS
CVECVSSEPSSNote
CVE-2026-1540910.0.8366KEV
CVE-2026-4828210.0.4239KEV
CVE-2026-5629010.0.3038KEV
CVE-2026-4893910.0.1973KEV
CVE-2026-4890810.0.1482KEV
CVE-2026-5629110.0.1459KEV
CVE-2026-5972610.0.0688
CVE-2026-898510.0.0660
CVE-2026-1377310.0.0610
CVE-2026-651610.0.0486
Most disclosures (vendor)
VendorCVEs
oracle1109
linux834
microsoft665
google503
apache175
apple167
red hat146
adobe115
ibm113
mozilla72
Most KEV additions (YTD)
VendorKEV
microsoft24
cisco12
apple7
fortinet6
google6
ivanti5
solarwinds4
adobe3
berriai3
oracle3
Most-affected ecosystems
EcosystemAdvisories
Maven72
PyPI6
NuGet4
npm4
Go3
Packagist2
crates.io2
Fastest to KEV
CVEVendorDays
CVE-2021-27137DD-WRT0
CVE-2025-68686Fortinet0
CVE-2026-0770Langflow0
CVE-2026-15409SonicWall0
CVE-2026-15410SonicWall0
CVE-2026-16232checkpoint0
CVE-2026-16812Arista Networks0
CVE-2026-20316Cisco0
CVE-2026-25089Fortinet0
CVE-2026-45659Microsoft0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171715
CVE-2021-27102n/a2021-11-171715
CVE-2021-27101n/a2021-11-171715
CVE-2021-27103n/a2021-11-171715
CVE-2021-21017Adobe2021-11-171715
CVE-2021-28550Adobe2021-11-171715
CVE-2021-42013Apache Software Foundation2021-11-171715
CVE-2021-41773Apache Software Foundation2021-11-171715
CVE-2021-30858Apple2021-11-171715
CVE-2021-30860Apple2021-11-171715

Transactions

EXPLOIT PUBLISHED — CVE-2021-29022. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2021-29023. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2021-29024. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2022-36271. Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2025-38352 (Linux). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-34632 (Adobe Photoshop Installer). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-45700 (FreeRDP). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-50289 (sebhildebrandt systeminformation). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-54497 (ViewComponent view_component). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-54498 (ViewComponent view_component). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-56821 (netty). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-59733 (rclone). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-59919 (netty). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-60113 (NASA-AMMOS AIT-DSN). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-66746 (tomaka rouille). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-66748 (owen2345 camaleon-cms). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-66754 (tomaka rouille). Public exploit reference added.

DUE DATE PASSED — CVE-2026-56155 (Microsoft Windows 10 Version 1607). CISA remediation deadline was July 28, 2026; still in catalog.

RESCORED — CVE-2024-21537 (lilconfig). CVSS 9.3 → 8.9 (NVD).

RESCORED — CVE-2026-11541 (IBM CICS Transaction Gateway for Multiplatforms). CVSS 7.4 → 9.8 (NVD).

RESCORED — CVE-2026-49181 (Microsoft Windows 10 Version 1607). CVSS 7.5 → 9.8 (NVD).

PATCH SHIPPED — CVE-2025-38352 (Linux). Fixed in Linux 5.4.295.

ENRICHED — CVE-2021-29022. Received CVSS 5.3 and CPE data from NVD.

ENRICHED — CVE-2021-29023. Received CVSS 5.3 and CPE data from NVD.

ENRICHED — CVE-2021-29024. Received CVSS 7.5 and CPE data from NVD.

ENRICHED — CVE-2026-53376 (Linux). Received CVSS 5.5 and CPE data from NVD.

ENRICHED — CVE-2026-53377 (Linux). Received CVSS 5.5 and CPE data from NVD.

Yesterday's Results

How to read these box scores · glossary

274 CVEs published. 25 box scores, 249 table rows — nothing truncated.

Cisco Secure Firewall Management Center Software Static Credential Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  L  N  N    5.3   .0982   95.2   YES
AFFECTED
  Product                                        Versions  Fixed
  Cisco Secure Firewall Management Center (FMC)  7.0.0 –   —
TIMELINE
  Oct 8   Reserved by CNA
  Jul 29  Added to CISA KEV, due Aug 1
  Jul 29  Published (CNA: cisco)
CWE-259 · CNA: cisco · CVSS v3.1 · 2 references · NVD status: Analyzed · KEV due August 1, 2026
DriveLock Directory Traversal Information Disclosure Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  N  N    6.5   .0160   73.9     —
AFFECTED
  Product    Versions        Fixed
  DriveLock  25.2.2.61370 –  —
TIMELINE
  Apr 3   Reserved by CNA
  Jul 29  Published (CNA: zdi)
CWE-22 · CNA: zdi · CVSS v3.0 · 2 references · NVD status: Deferred
DriveLock Directory Traversal Information Disclosure Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0154   73.0     —
AFFECTED
  Product    Versions        Fixed
  DriveLock  25.2.2.61370 –  —
TIMELINE
  Apr 3   Reserved by CNA
  Jul 29  Published (CNA: zdi)
CWE-22 · CNA: zdi · CVSS v3.0 · 2 references · NVD status: Deferred
DriveLock Directory Traversal Information Disclosure Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  N    7.5   .0154   72.9     —
AFFECTED
  Product    Versions        Fixed
  DriveLock  25.2.2.61370 –  —
TIMELINE
  Apr 3   Reserved by CNA
  Jul 29  Published (CNA: zdi)
CWE-22 · CNA: zdi · CVSS v3.0 · 2 references · NVD status: Deferred
DriveLock Directory Traversal Information Disclosure Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  L  N  N    5.3   .0127   67.5     —
AFFECTED
  Product    Versions        Fixed
  DriveLock  25.2.2.61370 –  —
TIMELINE
  Apr 3   Reserved by CNA
  Jul 29  Published (CNA: zdi)
CWE-22 · CNA: zdi · CVSS v3.0 · 2 references · NVD status: Deferred
OliveTin OS Command Injection via Custom regex: Argument Type Bypassing Shell Safety Check
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   H   N  U  H  H  H    6.6   .0100   60.0     —
AFFECTED
  Product   Versions                    Fixed
  OliveTin  >= 3000.2.0, < 3000.17.0 –  —
TIMELINE
  Jul 29  Reserved by CNA
  Jul 29  Published (CNA: GitHub_M)
CWE-78 · CNA: GitHub_M · CVSS v3.1 · 3 references · NVD status: Deferred
TP-Link Systems Inc. TL-WR940N v6 — Unauthenticated Remote Code Execution in TP-Link TL-WR940N RTSP Conntrack Feature
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   P   H   H   H    8.7   .0091   57.3     —
AFFECTED
  Product       Versions     Fixed
  TL-WR940N v6  unspecified  —
TIMELINE
  Jun 22  Reserved by CNA
  Jul 29  Published (CNA: TPLink)
CWE-121 · CNA: TPLink · CVSS v4.0 · 4 references · NVD status: Deferred
nico23 Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … — Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … 10.8.7 - Unauthenticated Authentication Bypass via Hardcoded Backdoor in '_wplogin' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0088   56.3     —
AFFECTED
  Product                                                                        Versions  Fixed
  Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick …  10.8.7 –  —
TIMELINE
  Jul 28  Reserved by CNA
  Jul 29  Published (CNA: Wordfence)
CWE-506 · CNA: Wordfence · CVSS v3.1 · 5 references · NVD status: Deferred
Care Everywhere Gateway 14.3.10 Hard-coded Credentials RCE via WildFly
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0080   53.9     —
AFFECTED
  Product                  Versions   Fixed
  Care Everywhere Gateway  14.3.10 –  —
TIMELINE
  Apr 22  Reserved by CNA
  Jul 29  Published (CNA: VulnCheck)
CWE-1392 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Deferred
7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   N   R  U  H  H  H    7.8   .0074   51.9     —
AFFECTED
  Product  Versions  Fixed
  7-Zip    26.01 –   —
TIMELINE
  Jun 30  Reserved by CNA
  Jul 29  Published (CNA: zdi)
CWE-122 · CNA: zdi · CVSS v3.1 · 2 references · NVD status: Analyzed
Heimdall Data Database Proxy generateFileContent CRLF Injection Remote Code Execution Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0073   51.3     —
AFFECTED
  Product         Versions       Fixed
  Database Proxy  25.03.01.21 –  —
TIMELINE
  Jun 15  Reserved by CNA
  Jul 29  Published (CNA: zdi)
CWE-93 · CNA: zdi · CVSS v3.0 · 1 reference · NVD status: Awaiting Analysis
aimy-extensions.com Aimy Captcha-Less Form Guard plugin for Joomla — Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H   10.0   .0071   50.7     —
AFFECTED
  Product                                         Versions     Fixed
  Aimy Captcha-Less Form Guard plugin for Joomla  18.0-20.0 –  —
TIMELINE
  Jul 23  Reserved by CNA
  Jul 29  Published (CNA: Joomla)
CWE-502 · CNA: Joomla · CVSS v4.0 · 1 reference · NVD status: Analyzed
StylemixThemes Cost Calculator Builder PRO — Cost Calculator Builder PRO <= 4.0.3 - Unauthenticated Remote Code Execution via 'orderDetails' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0069   50.0     —
AFFECTED
  Product                      Versions     Fixed
  Cost Calculator Builder PRO  unspecified  —
TIMELINE
  Jul 6   Reserved by CNA
  Jul 29  Published (CNA: Wordfence)
CWE-94 · CNA: Wordfence · CVSS v3.1 · 2 references · NVD status: Deferred
Xlight FTP Server < 3.9.5 Pre-Auth Stack Buffer Overflow via SSH GCM Cipher
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   H   H   H    9.2   .0066   48.7     —
AFFECTED
  Product            Versions     Fixed
  Xlight FTP Server  unspecified  —
TIMELINE
  Jul 28  Reserved by CNA
  Jul 29  Published (CNA: VulnCheck)
CWE-121 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Deferred
Xlight FTP Server < 3.9.5 Pre-Auth Heap Buffer Overflow via SSH Parser
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0062   46.8     —
AFFECTED
  Product            Versions     Fixed
  Xlight FTP Server  unspecified  —
TIMELINE
  Jul 28  Reserved by CNA
  Jul 29  Published (CNA: VulnCheck)
CWE-122 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Deferred
smub Easy Digital Downloads – eCommerce Payments and Subscriptions made easy — Easy Digital Downloads <= 3.6.9 - Authenticated (Shop Manager+) Arbitrary File Upload via 'edd-import-file' Parameter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0061   46.6     —
AFFECTED
  Product                                                                  Versions     Fixed
  Easy Digital Downloads – eCommerce Payments and Subscriptions made easy  unspecified  —
TIMELINE
  Jun 16  Reserved by CNA
  Jul 29  Published (CNA: Wordfence)
CWE-434 · CNA: Wordfence · CVSS v3.1 · 8 references · NVD status: Deferred
Autel MaxiCharger AC Elite Home WebSockets Integer Underflow Remote Code Execution Vulnerability
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  H  H  H    8.1   .0057   44.4     —
AFFECTED
  Product                    Versions   Fixed
  MaxiCharger AC Elite Home  1.39.51 –  —
TIMELINE
  Jun 25  Reserved by CNA
  Jul 29  Published (CNA: zdi)
CWE-191 · CNA: zdi · CVSS v3.0 · 1 reference · NVD status: Awaiting Analysis
Unknown Streamit — Streamit <= 4.5.0 - Unauthenticated Remote Code Execution via Arbitrary Function Call
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0054   42.8     —
AFFECTED
  Product   Versions     Fixed
  Streamit  unspecified  —
TIMELINE
  Jun 26  Reserved by CNA
  Jul 29  Published (CNA: WPScan)
CWE-94 · CNA: WPScan · CVSS v3.1 · 1 reference · NVD status: Deferred
ThemeComplete Extra Checkout Options - addon for Extra Product Options plugin — Extra Checkout Options (addon for Extra Product Options & Add-Ons for WooCommerce) <= 2.3.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Upload in eco_save_settings
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0053   42.5     —
AFFECTED
  Product                                                          Versions     Fixed
  Extra Checkout Options - addon for Extra Product Options plugin  unspecified  —
TIMELINE
  Jun 30  Reserved by CNA
  Jul 29  Published (CNA: Wordfence)
CWE-434 · CNA: Wordfence · CVSS v3.1 · 2 references · NVD status: Deferred
NASA-AMMOS AIT-GUI — AIT-GUI < 2.5.1 Missing Authentication via Sessions.create()
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0053   42.3     —
AFFECTED
  Product  Versions     Fixed
  AIT-GUI  unspecified  —
TIMELINE
  Jul 8   Reserved by CNA
  Jul 29  Published (CNA: VulnCheck)
CWE-306 · CNA: VulnCheck · CVSS v4.0 · 4 references · NVD status: Analyzed
webreinvent vaahcms — VaahCMS 2.0.0 - 2.3.4 Malicious JavaScript Supply Chain via security-otp.blade.php
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   H   H   H    9.2   .0053   42.3     —
AFFECTED
  Product  Versions  Fixed
  vaahcms  2.0.0 –   8d7898f7a385a5fade1180a9b664ff158d873129
TIMELINE
  Jul 29  Reserved by CNA
  Jul 29  Published (CNA: VulnCheck)
CWE-506 · CNA: VulnCheck · CVSS v4.0 · 3 references · NVD status: Deferred
NASA-AMMOS AIT-DSN — AIT-DSN < 2.2.2 Missing Authentication via SLE API Routes
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .0053   42.1     —
AFFECTED
  Product  Versions     Fixed
  AIT-DSN  unspecified  —
TIMELINE
  Jul 8   Reserved by CNA
  Jul 29  Public exploit reference published
  Jul 29  Published (CNA: VulnCheck)
CWE-306 · CNA: VulnCheck · CVSS v4.0 · 5 references · NVD status: Analyzed
Apache Traffic Server: Abusive HTTP/2 framing can exhaust resources and crash the server
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   H    8.7   .0052   42.0     —
AFFECTED
  Product                Versions  Fixed
  Apache Traffic Server  8.0.0 –   —
TIMELINE
  Jun 29  Reserved by CNA
  Jul 29  Published (CNA: apache)
CWE-400 · CNA: apache · CVSS v4.0 · 1 reference · NVD status: Analyzed
Apache Traffic Server: HTTP/2 and HTTP/3 dechunking removes per-stream buffer cap, allowing memory exhaustion
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   N   N   H    8.2   .0052   42.0     —
AFFECTED
  Product                Versions  Fixed
  Apache Traffic Server  8.0.0 –   —
TIMELINE
  Jul 21  Reserved by CNA
  Jul 29  Published (CNA: apache)
CWE-400 · CNA: apache · CVSS v4.0 · 1 reference · NVD status: Analyzed
Apache Kyuubi: Unrestricted access via Kyuubi engine-ui proxy
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  L  L  L    7.3   .0052   42.1     —
AFFECTED
  Product        Versions  Fixed
  Apache Kyuubi  1.8.0 –   —
TIMELINE
  Jan 19  Reserved by CNA
  Jul 29  Published (CNA: apache)
CWE-923 · CNA: apache · CVSS v3.1 · 3 references · NVD status: Analyzed
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-667237.040.2CERT.PLMWDB CoreCWE-862Missing authentication requirement in Remote Instances proxy API in MWDB Core
CVE-2026-119748.639.8Unknownwp-media-folder-addonCWE-22Media folder Addon < 4.1.7 - Unauthenticated Arbitrary File Download
CVE-2026-6742910.039.8flytohubflyto-coreCWE-22Flyto2 Core: Arbitrary file write via image.download (and other file-writing …
CVE-2026-50577.539.5ATENUnizonCWE-306ATEN Unizon RpcProvider Missing Authentication Denial-of-Service Vulnerability
CVE-2026-54908.839.3DriveLockDriveLockCWE-89DriveLock SQL Injection Privilege Escalation Vulnerability
CVE-2026-159757.538.8GitLabGitLabCWE-770Allocation of Resources Without Limits or Throttling in GitLab
CVE-2026-137236.538.2Develarapp-builderCWE-22Develar's electron-builder allows arbitrary file overwrite
CVE-2026-136979.138.1undiciundiciCWE-200undici vulnerable to cross-user information disclosure and parse-time crash v…
CVE-2026-672158.738.1DaveGamblecJSONCWE-674cJSON JSON Patch copy/add Uncontrolled Recursion Stack Exhaustion
CVE-2026-581536.338.1Apache Software FoundationApache Traffic ServerCWE-444Apache Traffic Server: HTTP/2 to HTTP/1 conversion forwards origin trailers t…
CVE-2026-592439.836.9Apache Software FoundationApache Airflow FAB providerCWE-347Apache Airflow FAB provider: FAB auth manager: JWT signature verification dis…
CVE-2026-581619.236.6Apache Software FoundationApache Traffic ServerCWE-476Apache Traffic Server: Memory-safety errors in TLS and SNI handling can crash…
CVE-2026-581888.435.8Apache Software FoundationApache Traffic ServerCWE-787Apache Traffic Server: Memory-safety and limit-bypass errors across experimen…
CVE-2026-674327.535.6modelcontextprotocolruby-sdkCWE-770MCP Ruby SDK: Unbounded JSON-RPC request body causes uncontrolled memory allo…
CVE-2026-672168.235.3DaveGamblecJSONCWE-407cJSON cJSON_Compare Exponential Complexity Denial of Service
CVE-2026-546809.935.3kube-logginglogging-operatorCWE-74Logging operator has Fluentd configuration injection that allows remote code …
CVE-2026-581828.235.1Apache Software FoundationApache Traffic ServerCWE-400Apache Traffic Server: ts_lua plugin has initialization and resource-handling…
CVE-2026-466785.934.6pydanticpydantic-aiCWE-918Pydantic AI: SSRF cloud-metadata blocklist bypass via IPv4-mapped IPv6 (Incom…
CVE-2026-581606.334.5Apache Software FoundationApache Traffic ServerCWE-125Apache Traffic Server: Out-of-bounds reads while parsing DNS responses
CVE-2026-581868.234.4Apache Software FoundationApache Traffic ServerCWE-20Apache Traffic Server: webp_transform plugin decodes unsafely and mislabels d…
CVE-2026-220686.933.8Apache Software FoundationApache Traffic ServerCWE-777Apache Traffic Server: Regex mappings match with malicious domain names
CVE-2026-581559.233.3Apache Software FoundationApache Traffic ServerCWE-444Apache Traffic Server: Header-name length truncation enables header aliasing …
CVE-2026-581758.232.9Apache Software FoundationApache Traffic ServerCWE-401Apache Traffic Server: HostDB SRV handling leaks memory
CVE-2026-581788.232.9Apache Software FoundationApache Traffic ServerCWE-674Apache Traffic Server: ESI plugin allows uncontrolled recursion and server-si…
CVE-2026-581808.232.9Apache Software FoundationApache Traffic ServerCWE-121Apache Traffic Server: txn_box plugin overflows the stack from attacker input
CVE-2026-645607.832.7LinuxLinux—posix-cpu-timers: Prevent UAF caused by non-leader exec() race
CVE-2026-581549.232.7Apache Software FoundationApache Traffic ServerCWE-787Apache Traffic Server: Memory-safety errors in MIME and header parsing
CVE-2026-50567.832.6GStreamerGStreamerCWE-121GStreamer qtdemux Stack-based Buffer Overflow Remote Code Execution Vulnerabi…
CVE-2026-145299.832.4IBMWebSphere Application ServerCWE-306IBM WebSphere Application Server and WebSphere Application Server Liberty are…
CVE-2026-581648.332.0Apache Software FoundationApache Traffic ServerCWE-416Apache Traffic Server: Remap configuration lifetime and TOCTOU errors cause u…
CVE-2026-581818.232.0Apache Software FoundationApache Traffic ServerCWE-121Apache Traffic Server: uri_signing and url_sig plugins can exhaust the stack …
CVE-2026-581838.231.8Apache Software FoundationApache Traffic ServerCWE-20Apache Traffic Server: prefetch plugin can crash on attacker-influenced input
CVE-2026-672017.731.9vlangvCWE-436V 0.5.2 SSRF Bypass via Parser Differential in net.urllib and net.http
CVE-2026-119734.931.3wp-labWP-Lister Lite for eBayCWE-89WP-Lister Lite for eBay <= 3.8.8 - Authenticated (Shop Manager+) SQL Injectio…
CVE-2026-181919.331.1VacronVIN-DS783E-E6CWE-912Vacron|IP Camera - Hidden Functionality
CVE-2026-581638.331.0Apache Software FoundationApache Traffic ServerCWE-502Apache Traffic Server: Cache deserialization and lifetime errors can corrupt …
CVE-2026-339308.230.8Apache Software FoundationApache Traffic ServerCWE-121Apache Traffic Server: Buffer overflow via Host field that has a long string …
CVE-2026-181927.130.8VacronVIN-DS783E-E6CWE-23Vacron|IP Camera - Arbitrary File Read
CVE-2026-578347.030.7Apache Software FoundationApache Traffic ServerCWE-444Apache Traffic Server: Malformed chunked message body allows request smuggling
CVE-2026-182369.330.4GoogleGoogle-ADKCWE-863Google-ADK Continuation Forgery
CVE-2026-332677.730.3Apache Software FoundationApache Traffic ServerCWE-20Apache Traffic Server: Untrusted @ headers can spoof ATS internal metadata
CVE-2026-06679.329.6Schneider ElectricSCADAPack 47xCWE-754CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability t…
CVE-2026-581507.829.3Apache Software FoundationApache Traffic ServerCWE-444Apache Traffic Server: HTTP/2 requests with Transfer-Encoding are not rejecte…
CVE-2026-581799.229.3Apache Software FoundationApache Traffic ServerCWE-121Apache Traffic Server: regex_remap plugin overflows the stack from attacker i…
CVE-2026-658869.229.1balbooa.comGridbox extension for JoomlaCWE-22Joomla Extension - balbooa.com - Unauthenticated arbitrary file read in Gridb…
CVE-2025-106569.828.9holestSpreadsheet Price Changer for WooCommerce and WP E-commerce – LightCWE-863Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light <= 2.4.37…
CVE-2026-581898.228.6Apache Software FoundationApache Traffic ServerCWE-918Apache Traffic Server: Plugins resetting the redirect counter enable SSRF amp…
CVE-2026-674278.628.5flytohubflyto-coreCWE-522Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get be…
CVE-2026-121448.828.4saadiqbalWholesale for WooCommerceCWE-269Wholesale for WooCommerce <= 2.0.5 - Authenticated (Author+) Privilege Escala…
CVE-2026-651006.328.1Apache Software FoundationApache Traffic ServerCWE-696Apache Traffic Server: HPACK encoder desynchronizes from the decoder after a …
CVE-2026-674377.527.6OliveTinOliveTinCWE-400OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded M…
CVE-2026-581848.327.5Apache Software FoundationApache Traffic ServerCWE-787Apache Traffic Server: header_rewrite plugin cookie handling can corrupt memory
CVE-2026-507827.527.5n/an/aCWE-611Jinher OA C6 contains an XML External Entity (XXE) injection vulnerability in…
CVE-2026-5473510.027.1prebidprebid-serverCWE-918prebid-server's request forgery vulnerability allows for possible host enviro…
CVE-2026-581588.227.0Apache Software FoundationApache Traffic ServerCWE-121Apache Traffic Server: PROXY protocol parsing has port truncation and a stack…
CVE-2026-581526.927.0Apache Software FoundationApache Traffic ServerCWE-190Apache Traffic Server: Integer-handling errors in HPACK/XPACK decoding corrup…
CVE-2026-581876.327.0Apache Software FoundationApache Traffic ServerCWE-787Apache Traffic Server: Multiplexer plugin chunk decoder enables a denial of s…
CVE-2026-153444.927.1opajaapWP Photo Album PlusCWE-89WP Photo Album Plus <= 9.2.04.002 - Authenticated (Administrator+) SQL Inject…
CVE-2026-546938.226.8zitadelzitadelCWE-863ZITADEL Users Can Self-Verify Email/Phone via API
CVE-2026-581858.226.2Apache Software FoundationApache Traffic ServerCWE-416Apache Traffic Server: Use-after-free in the intercept plugin
CVE-2026-674288.526.1flytohubflyto-coreCWE-918Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs withou…
CVE-2026-506228.826.0Apache Software FoundationApache AtlasCWE-862Apache Atlas: Missing Authorization on Admin Endpoints
CVE-2026-598996.925.9nettynettyCWE-770Netty HttpContentEncoder: Unbounded Per-Connection Queue Growth via HTTP/1.1 …
CVE-2026-180228.825.8n/apgvectorCWE-190pgvector buffer overflow via integer wraparound in IVFFlat index build on 32-…
CVE-2026-62675.325.7GitLabGitLabCWE-201Insertion of Sensitive Information Into Sent Data in GitLab
CVE-2026-672148.225.3nanoid_projectnanoidCWE-835nanoid Infinite Loop via Negative Size in non-secure module
CVE-2026-449436.925.4open-iscsiopen-iscsiCWE-22remote limited file-write as root via discovery in open-iscsi
CVE-2026-632279.925.1An unrestricted SCORM file upload vulnerability in Koollab LMS allowed an authenticated module designer to upload a SCORM package containing a PHP webshell to a publicly accessible directory and execute arbitrary code on the server.Koollab LMSCWE-434Unrestricted SCORM file upload vulnerability
CVE-2026-581778.325.0Apache Software FoundationApache Traffic ServerCWE-787Apache Traffic Server: Memory-safety and path-traversal errors in the Cripts …
CVE-2026-240336.924.9Apache Software FoundationApache Traffic ServerCWE-444Apache Traffic Server: Request smuggling via chunked extension quoted-string …
CVE-2026-143414.924.9GitLabGitLabCWE-862Missing Authorization in GitLab
CVE-2026-540788.724.2veraPDFveraPDF-validationCWE-611veraPDF Validation XXE via Rich Text
CVE-2026-540798.724.2veraPDFveraPDF-validationCWE-611veraPDF Validation XXE via XFA
CVE-2026-674258.624.2flytohubflyto-coreCWE-201Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url
CVE-2026-672138.224.1nanoid_projectnanoidCWE-835nanoid before 5.1.6 Infinite Loop via Zero Size in customAlphabet and customR…
CVE-2026-581597.023.9Apache Software FoundationApache Traffic ServerCWE-863Apache Traffic Server: Listener and ACL handling allow access-control bypass
CVE-2026-124368.423.1GitLabGitLabCWE-915Improperly Controlled Modification of Dynamically-Determined Object Attribute…
CVE-2026-419207.023.0Apache Software FoundationApache Traffic ServerCWE-284Apache Traffic Server: SNI to Host header matching policy is not properly enf…
CVE-2026-674269.322.9flytohubflyto-coreCWE-306Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and i…
CVE-2026-674305.322.9modelcontextprotocolruby-sdkCWE-401MCP Ruby SDK: Unbounded session retention in StreamableHTTPTransport allows m…
CVE-2026-144889.122.8Meta BoxMeta Box AIOCWE-862Meta Box AIO <= 3.8.0 - Missing Authorization to Unauthenticated Arbitrary Po…
CVE-2026-671947.122.6svarshavchikCourier IMAPCWE-674Courier IMAP < 6.0.1 Mail Server < 2.0.2 Stack Overflow DoS via Nested SEARCH…
CVE-2026-146437.522.4undiciundiciCWE-436undici vulnerable to cross-user information disclosure via whitespace around …
CVE-2026-166557.222.4wpmanageninjaFluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form BuilderCWE-79Fluent Forms <= 6.2.7 - Unauthenticated Stored Cross-Site Scripting via Name …
CVE-2026-540806.922.2veraPDFveraPDF-parserCWE-1325veraPDF Parser DoS via PostScript CMap Streams
CVE-2026-540816.922.2veraPDFveraPDF-parserCWE-1325veraPDF Parser DoS via PostScript Type 1 Font Programs
CVE-2026-6588710.022.1balbooa.comGridbox extension for JoomlaCWE-284Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in …
CVE-2026-83389.222.0Black DuckCoverity ConnectCWE-288Authentication and Authorization Bypass in Coverity Connect
CVE-2026-506424.822.0so-fancydiff-so-fancyCWE-116Terminal Escape Injection in diff‑so‑fancy
CVE-2026-1632610.021.9HashiCorpToolingCWE-488consul-mcp-server vulnerable to cross-tenant credential reuse in streamable-H…
CVE-2026-672176.921.8DaveGamblecJSONCWE-696cJSON JSON Patch Non-Atomic Application Destroys Data Before Validation
CVE-2026-632299.121.6Three LearningKoollab LMSCWE-89Pre-authentication blind SQL injection vulnerability
CVE-2026-632309.121.6Three LearningKoollab LMSCWE-89Pre-authentication error-based SQL injection vulnerability
CVE-2026-182207.821.6Red HatRed Hat Enterprise Linux 10CWE-787Binutils: binutils: out-of-bounds write in bfd dlx elf backend relocation pro…
CVE-2026-167516.521.5EnteMuseum Server—Ente Museum Server Authorization Bypass Vulnerability
CVE-2026-143514.321.4GitLabGitLabCWE-1230Exposure of Sensitive Information Through Metadata in GitLab
CVE-2026-632329.921.4Three LearningKoollab LMSCWE-89SQL injection and unsafe deserialisation vulnerability
CVE-2026-632339.921.4Three LearningKoollab LMSCWE-89SQL injection and unsafe deserialisation vulnerability
CVE-2026-632349.921.4Three LearningKoollab LMSCWE-89SQL injection and unsafe deserialisation vulnerability
CVE-2026-658859.421.2balbooa.comGridbox extension for JoomlaCWE-434Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridb…
CVE-2026-674318.321.2modelcontextprotocolruby-sdkCWE-284MCP Ruby SDK: Ruby SSE Session Poisoning
CVE-2026-133465.621.2Python Packaging AuthoritypipCWE-36pip absolute path traversal during download from malicious package indexes
CVE-2026-6588810.021.0balbooa.comGridbox extension for JoomlaCWE-284Joomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < …
CVE-2026-658899.221.0balbooa.comGridbox extension for JoomlaCWE-284Joomla Extension - balbooa.com - Unauthenticated recursive directory deletion…
CVE-2026-91779.420.8AxwaySecureTransportCWE-1336Server-Side Template Injection in SecureTransport's Apache Velocity mail temp…
CVE-2026-546668.320.5acacodeswagger-typescript-apiCWE-74swagger-typescript-api vulnerable to code injection via unescaped OpenAPI pat…
CVE-2026-674356.020.6Linuxfabrikmonitoring-pluginsCWE-200linuxfabrik-lib: fetch() forwards credential headers across a cross-origin re…
CVE-2026-46724.320.5GitLabGitLabCWE-862Missing Authorization in GitLab
CVE-2026-6588410.020.4balbooa.comGridbox extension for JoomlaCWE-284Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2
CVE-2026-658909.220.1balbooa.comGridbox extension for JoomlaCWE-89Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2…
CVE-2026-671936.920.1XlightXlight FTP ServerCWE-203Xlight FTP Server < 3.9.5 Information Disclosure via USER Command
CVE-2025-699439.819.5n/an/aCWE-89kishan0725 Hospital Management System 4.0 is vulnerale to SQL Injection in ge…
CVE-2026-581576.919.2Apache Software FoundationApache Traffic ServerCWE-200Apache Traffic Server: Improper server-session reuse can expose data across c…
CVE-2026-182557.219.0Red HatRed Hat Quay 3CWE-863Quay: quay: global read-only superuser can view robot account tokens
CVE-2026-546618.318.7acacodeswagger-typescript-apiCWE-74swagger-typescript-api vulnerable to code injection via unescaped `servers[0]…
CVE-2026-546628.318.7acacodeswagger-typescript-apiCWE-74swagger-typescript-api vulnerable to code injection via unescaped `servers[0]…
CVE-2026-546648.318.7acacodeswagger-typescript-apiCWE-74swagger-typescript-api vulnerable to code injection via unescaped enum string…
CVE-2026-60894.918.6blendmediaWP CTA – Call Now Button, Sticky Button & Call to Action BuilderCWE-918WP CTA <= 2.1.2 - Authenticated (Administrator+) Server-Side Request Forgery
CVE-2026-667245.318.5CERT.PLMWDB CoreCWE-862Permission Bypass Via Undocumented HTTP Methods In MWDB Core
CVE-2026-599018.717.7nettynettyCWE-835Netty Bzip2Decoder: Infinite Loop in RLE State Machine Leads to Event-Loop Th…
CVE-2025-653409.817.3n/an/aCWE-89kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /…
CVE-2025-674039.817.3n/an/aCWE-89Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Inj…
CVE-2025-674049.817.3n/an/aCWE-89Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Inj…
CVE-2025-699429.817.4n/an/aCWE-89kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /…
CVE-2026-63365.316.7GitLabGitLabCWE-863Incorrect Authorization in GitLab
CVE-2026-136907.416.6UnknownUsersWPCWE-287UsersWP < 1.2.67 - Two-Factor Authentication Bypass
CVE-2026-658916.516.7joomlacontenteditor.netJoomla Content Editor (JCE) extension for JoomlaCWE-20Joomla Extension - joomlacontenteditor.net - Creation of hidden files and uni…
CVE-2026-165535.416.6GitLabGitLabCWE-522Insufficiently Protected Credentials in GitLab
CVE-2026-674394.316.4OliveTinOliveTinCWE-863OliveTin: StartActionAndWait Endpoints Bypass `logs` Permission and Return Ac…
CVE-2026-559958.716.3open-iscsiopen-iscsiCWE-415Double-free in the iSNS attribute decoder in open-iscsi
CVE-2026-632318.116.4Three LearningKoollab LMSCWE-89Post-authentication SQL injection vulnerability
CVE-2026-150774.316.2GitLabGitLabCWE-74Improper Neutralization of Input Used for LLM Prompting in GitLab
CVE-2026-505585.916.1brightiopenelopeCWE-22Penelope unsafe tar extraction allows arbitrary local file write via crafted …
CVE-2026-674368.316.0Linuxfabrikmonitoring-pluginsCWE-20Linuxfabrik monitoring-plugins: SSRF and auth-token disclosure via unvalidate…
CVE-2026-598986.316.0nettynettyCWE-444Netty: WebSockets V07/V08 handshaker missing Connection/Upgrade validation
CVE-2026-134257.215.9code4lifeDatabase for CF7CWE-79Database for CF7 <= 1.2.6 - Unauthenticated Stored Cross-Site Scripting via A…
CVE-2026-581566.315.9Apache Software FoundationApache Traffic ServerCWE-863Apache Traffic Server: URL and port parsing errors allow access-control bypass
CVE-2026-182665.415.9LangGeniusDifyCWE-601Dify AI Workflow oauth_redirect_url Open Redirect Vulnerability
CVE-2026-151445.315.7@fastify/rate-limit@fastify/rate-limitCWE-307@fastify/rate-limit vulnerable to rate-limit bypass via IPv6 address rotation
CVE-2026-546607.415.3acacodeswagger-typescript-apiCWE-200swagger-typescript-api vulnerable to authorization-token exfiltration via spe…
CVE-2026-645578.814.9LinuxLinux—Bluetooth: L2CAP: Fix use-after-free in l2cap_sock_new_connection_cb()
CVE-2026-165977.215.0duracelltomiGTM4WP – A Google Tag Manager (GTM) plugin for WordPressCWE-79GTM4WP <= 1.22.3 - Unauthenticated Stored Cross-Site Scripting via WooCommerc…
CVE-2026-333855.114.9OpenSolutionQuick.CMSCWE-89Blind SQL Injection in Quick.CMS
CVE-2026-143008.114.7UnknownminiOrange Social Login and Register (Discord, Google, Twitter, LinkedIn)CWE-287miniOrange Social Login and Register < 7.8.0 - Unauthenticated Account Takeover
CVE-2026-599206.514.7nettynettyCWE-93Netty: STOMP CONNECT Frame Header Injection
CVE-2026-674248.514.4flytohubflyto-coreCWE-918Flyto2 Core: Guarded HTTP modules follow redirects into internal space withou…
CVE-2026-46045.314.2klubraumKlubraum Membership RequestCWE-862Klubraum Membership Request <= 1.1.0 - Missing Authorization to Unauthenticat…
CVE-2026-30934.714.2GitLabGitLabCWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scri…
CVE-2026-127038.014.1TeamViewerRemoteCWE-288Bypass of 2FA for Connections via Unattended Access in TeamViewer for macOS
CVE-2026-87916.414.1ameliabookingBooking System TrafftCWE-79Booking System Trafft <= 1.0.17 - Authenticated (Subscriber+) Stored Cross-Si…
CVE-2026-163288.613.9HashiCorpToolingCWE-918consul-mcp-server vulnerable to server side request forgery leading to token …
CVE-2025-609317.513.9n/an/aCWE-639An Insecure Direct Object Reference (IDOR) in the Employee Compensation View …
CVE-2026-659437.513.9rolandd.comRO CSVI extension for JoomlaCWE-284Joomla Extension - rolandd.com - Unauthenticated directory creation RO CSVI <…
CVE-2026-599006.913.9nettynettyCWE-444Netty codec-http2: Lack of Host Header Deduplication in HTTP/2→HTTP/1.x Trans…
CVE-2026-540826.513.6veraPDFveraPDF-validationCWE-611veraPDF-validatio: Use of Default `DocumentBuilderFactory` leads to XXE When …
CVE-2026-136056.813.4UnknownPhotoSwipeCWE-79Photo Swipe <= 4.1.1.1 - Author+ Stored XSS via title Attribute
CVE-2026-133076.813.3AutelMaxiCharger AC Elite HomeCWE-122Autel MaxiCharger AC Elite Home USB Heap-based Buffer Overflow Arbitrary Code…
CVE-2026-133096.813.3AutelMaxiCharger AC Elite HomeCWE-121Autel MaxiCharger AC Elite Home NFC Stack-based Buffer Overflow Arbitrary Cod…
CVE-2026-581628.412.9Apache Software FoundationApache Traffic ServerCWE-295Apache Traffic Server: Certifier plugin trusts client SNI when generating cer…
CVE-2026-171664.313.0magepeopleteamEvent Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event CalendarCWE-862Event Booking Manager for WooCommerce <= 5.3.7 - Missing Authorization to Aut…
CVE-2025-145623.112.9GitLabGitLabCWE-863Incorrect Authorization in GitLab
CVE-2026-182076.512.6Red HatRed Hat Build of KeycloakCWE-285Keycloak-services: keycloak-services: client policy source-group condition by…
CVE-2026-158314.312.5GitLabGitLabCWE-1270Generation of Incorrect Security Tokens in GitLab
CVE-2026-182015.511.9Red HatRed Hat Build of KeycloakCWE-862Keycloak-services: keycloak-services: generic identity-provider creation can …
CVE-2026-128957.111.8FrappeERPNextCWE-89SQL Injection in Frappe's ERPNext
CVE-2026-632386.511.9Three LearningKoollab LMSCWE-287Authentication bypass vulnerability
CVE-2026-50606.511.6stylemixMasterStudy LMS WordPress Plugin – for Online Courses and EducationCWE-639MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.14…
CVE-2026-547056.310.9arnogmathliveCWE-116mathlive's Lack of Escaping of HTML allows for XSS
CVE-2026-129386.410.6contridNewslettersCWE-79Newsletters <= 4.15 - Authenticated (Contributor+) Stored Cross-Site Scriptin…
CVE-2026-129396.410.6contridNewslettersCWE-79Newsletters <= 4.15 - Authenticated (Contributor+) Stored Cross-Site Scriptin…
CVE-2026-113515.310.6UnknownShinyStat AnalyticsCWE-200ShinyStat Analytics < 1.0.17 - Unauthenticated Non-Published Product Informat…
CVE-2026-664895.310.4balbooa.comGridbox extension for JoomlaCWE-200Joomla Extension - balbooa.com - Various unauthenticated file system disclosu…
CVE-2026-664885.310.3balbooa.comGridbox extension for JoomlaCWE-285Joomla Extension - balbooa.com - Payment bypass in Gridbox < 2.20.2
CVE-2026-83398.710.2Black DuckCoverity ConnectCWE-89SQL Injection in Coverity Connect SOAP API
CVE-2025-674067.310.1n/an/aCWE-89https://www.sourcecodester.com Advocate office management system 1.0 is affec…
CVE-2026-131135.39.8GitLabGitLabCWE-367Time-of-check Time-of-use (TOCTOU) Race Condition in GitLab
CVE-2026-56264.39.7bpluginsSurvey Form Block – collect answers and insights from your audienceCWE-862Survey Form Block <= 1.0.1 - Missing Authorization to Authenticated (Subscrib…
CVE-2026-646855.39.5ImageMagickImageMagickCWE-125ImageMagick: Heap Buffer Over-Read in BGR decoder due to mising end-of-file c…
CVE-2026-542496.89.4pydanticpydantic-aiCWE-918VercelAIAdapter trusts client-controlled `providerMetadata` to construct `Upl…
CVE-2026-659756.59.4pydanticpydantic-aiCWE-863Pydantic AI AG-UI Adapter: A dangling client-submitted tool call can execute …
CVE-2026-632353.79.3Three LearningKoollab LMSCWE-284Improper access control vulnerability
CVE-2026-631186.99.2modelcontextprotocolruby-sdkCWE-346MCP Ruby SDK: Streamable HTTP transport lacks DNS-rebinding (Host/Origin) pro…
CVE-2026-151575.48.9undiciundiciCWE-93undici vulnerable to CRLF Injection via blob-like body 'type' property
CVE-2026-181745.38.9@fastify/forwarded@fastify/forwardedCWE-20@fastify/forwarded vulnerable to improper input validation via unstripped tab…
CVE-2026-167296.58.7undiciundiciCWE-74undici vulnerable to cookie attribute injection via unsanitized domain and un…
CVE-2026-164637.88.6AutodeskAutoCADCWE-122DXF File Parsing Heap-Based Overflow in Autodesk AutoCAD
CVE-2026-74366.48.4wpcleverWPC Badge Management for WooCommerceCWE-79WPC Badge Management for WooCommerce <= 3.1.6 - Authenticated (Contributor+) …
CVE-2026-157356.48.4itpathsolutionsContact Form to Any APICWE-79Contact Form to Any API <= 3.0.6 - Authenticated (Contributor+) Stored Cross-…
CVE-2026-171616.48.4wpxpoWowStore – Store Builder & Product Blocks for WooCommerceCWE-79WowStore <= 4.4.24 - Authenticated (Contributor+) Stored Cross-Site Scripting…
CVE-2026-171626.48.4wpxpoWowStore – Store Builder & Product Blocks for WooCommerceCWE-79WowStore <= 4.4.24 - Authenticated (Contributor+) Stored Cross-Site Scripting…
CVE-2026-133064.37.8AutelMaxiCharger AC Elite HomeCWE-306Autel MaxiCharger AC Elite Home USB Authentication Bypass Vulnerability
CVE-2026-136925.37.7UnknownPayU CommercePro PluginCWE-862PayU CommercePro < 3.9.0 - Unauthenticated Order Tampering
CVE-2026-546636.17.7acacodeswagger-typescript-apiCWE-20swagger-typescript-api vulnerable to Server-Side Request Forgery via spec `$ref`
CVE-2026-164657.17.4AutodeskAutoCADCWE-125DWG or DXF File Parsing Out-of-Bounds Read in Autodesk AutoCAD
CVE-2025-699497.37.1n/an/aCWE-89kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in c…
CVE-2026-167286.57.1undiciundiciCWE-444undici vulnerable to downstream response desynchronization via retry interceptor
CVE-2026-175505.57.1AutodeskAutoCADCWE-125DWG or DXF File Parsing Out-of-Bounds Read in Autodesk AutoCAD
CVE-2026-632404.37.1Three LearningKoollab LMSCWE-200Information disclosure vulnerability
CVE-2026-352267.16.7CODESYSCODESYS PROFINETCWE-787Out-of-bounds Write in CODESYS PROFINET Controller
CVE-2025-674057.36.4n/an/aCWE-89Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Inj…
CVE-2025-674077.36.4n/an/aCWE-89Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Inj…
CVE-2025-674087.36.4n/an/aCWE-89Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Inj…
CVE-2025-699447.36.4n/an/aCWE-89kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in t…
CVE-2025-699457.36.4n/an/aCWE-89kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /…
CVE-2026-632363.76.1Three LearningKoollab LMSCWE-284Improper access control vulnerability
CVE-2026-129278.45.3Schneider ElectricIGSS Definition (Def.exe)CWE-787CWE-787 Out-of-bounds write vulnerability exists that could cause loss of dat…
CVE-2026-506417.15.4StreamsoftBusiness IntelligenceCWE-256Plaintext password storage in Streamsoft Business Intelligence
CVE-2026-181976.45.0—Link LibraryCWE-79Improper neutralization of input during web page generation ('cross-site scri…
CVE-2026-653256.34.9Apache Software FoundationApache Traffic ServerCWE-295Apache Traffic Server: HTTP/2 multiplexed origin sessions are reused without …
CVE-2025-653376.14.8n/an/aCWE-79Sourcecodester Fantastic Blog CMS 1.0 is vulnerable to Cross Site Scripting (…
CVE-2026-664906.14.8balbooa.comGridbox extension for JoomlaCWE-79Joomla Extension - balbooa.com - Stored cross-site scripting via a comment av…
CVE-2026-563896.84.8GNUBisonCWE-78Arbitrary Command Execution in GNU Bison
CVE-2026-664006.34.6getgravgravCWE-613Grav Login Plugin before 3.8.13 Insufficient Session Expiration
CVE-2026-632424.34.6Three LearningKoollab LMSCWE-639Business logic vulnerability
CVE-2026-132687.84.5G DATATotal SecurityCWE-59G DATA Total Security Backup Service Link Following Local Privilege Escalatio…
CVE-2026-659466.14.3rolandd.comRO CSVI extension for JoomlaCWE-79Joomla Extension - rolandd.com - XSS vectors in AJAX endpoint handlers RO CSV…
CVE-2026-545748.24.0termuxproot-distroCWE-61`proot-distro install` has a Symlink Escape (Arbitrary Host File Write) via M…
CVE-2026-142245.43.7UnknownEasy AppointmentsCWE-639Easy Appointments < 3.12.28 - Subscriber+ Cross-User Appointment Data Modific…
CVE-2026-152287.13.6—Kong/kubernetes-ingress-controllerCWE-400Kong Kubernetes Ingress Controller cluster-wide ingress configuration DoS via…
CVE-2026-165437.13.6—Kong/kong-operatorCWE-400Kong Operator cluster-wide ingress configuration DoS via embedded KIC CA-cert…
CVE-2026-632413.13.6Three LearningKoollab LMSCWE-639Insecure direct object reference vulnerability
CVE-2026-599195.53.5nettynettyCWE-93Netty: HAProxy V1 Protocol CRLF Injection via AF_UNIX Address
CVE-2026-563904.63.0GNUBisonCWE-73Arbitrary Output Location Change in GNU Bison
CVE-2026-659448.82.9rolandd.comRO CSVI extension for JoomlaCWE-352Joomla Extension - rolandd.com - CSRF vectors in AJAX endpoint handlers RO CS…
CVE-2026-592477.62.6gleam-langgleamCWE-345Insufficient verification of Hex package metadata in Gleam
CVE-2026-97204.32.7facturadorvirtualFacturación Electrónica Costa RicaCWE-352Facturación Electrónica Costa Rica <= 2.0.2 - Cross-Site Request Forgery to P…
CVE-2026-632282.62.7Three LearningKoollab LMSCWE-434Unrestricted image upload vulnerability
CVE-2026-631196.22.6modelcontextprotocolruby-sdkCWE-400MCP Ruby SDK: Unbounded line buffer in stdio transports leads to memory exhau…
CVE-2026-659477.32.5balbooa.comGridbox extension for JoomlaCWE-352Joomla Extension - balbooa.com - Various CSRF vectors in the admin interface …
CVE-2026-645567.82.4LinuxLinux—perf/core: Detach event groups during remove_on_exec
CVE-2026-632395.42.2Three LearningKoollab LMSCWE-798Hard-coded AWS IAM credentials vulnerability
CVE-2026-547278.22.1termuxproot-distroCWE-668proot-distro has a Container Isolation Bypass via Crafted Restore Archive
CVE-2026-133056.42.1AutelMaxiCharger AC Elite HomeCWE-347Autel MaxiCharger AC Elite Home Software Update Improper Verification of Cryp…
CVE-2026-645587.82.0LinuxLinux—s390/pkey: Check length in pkey_pckmo handler implementation
CVE-2026-645597.82.0LinuxLinux—s390/pkey: Check length in PKEY_VERIFYPROTK ioctl
CVE-2026-143548.71.8Schneider ElectricEcoStruxure™ Cybersecurity Admin ExpertCWE-522CWE-522 Insufficiently Protected Credentials vulnerability exists that could …
CVE-2026-632374.81.8Three LearningKoollab LMSCWE-347TOTP two-factor authentication bypass vulnerability
CVE-2026-402727.01.5BlackBerry LtdQNX Software Development PlatformCWE-1284Vulnerability in the QNX libtraceparser Impacts QNX Software Development Plat…
CVE-2026-629952.31.2authlibjoserfcCWE-345joserfc accepts JWT with padding, leading to JWT malleability
CVE-2026-527912.01.0containersfuse-overlayfsCWE-266fuse-overlayfs release-1.x preserves SUID/SGID bits after truncate/open(O_TRUNC)
CVE-2026-182575.60.9SysterelS2OPCCWE-295Improper Certificate Validation in S2OPC
CVE-2026-106843.00.9zephyrprojectzephyrCWE-125Out-of-bounds read in coredump shell when printing stored-dump target code
CVE-2026-142347.10.9UnknownWOLFCWE-79WOLF - WordPress Posts Bulk Editor and Manager < 1.1.0 - Stored XSS via CSRF
CVE-2026-24828.80.9IBMWebSphere Application Server - LibertyCWE-352IBM WebSphere Application Server Liberty is affected by a cross-site request …
CVE-2026-449448.50.6open-iscsiopen-iscsiCWE-863iscsiuio control-socket authentication bypass in open-iscsi
CVE-2026-623434.70.5ImageMagickImageMagickCWE-190ImageMagick: Heap Buffer Over-Write in morphology operation when an invalid k…
CVE-2026-61027.80.4MSIMSI CenterCWE-346MSI Center NTIOLib_X64 Origin Validation Error Local Privilege Escalation Vul…
CVE-2026-84977.40.3DevolutionsPassword ManagerCWE-295Improper certificate validation in the Devolutions Server connection handling…
CVE-2026-674335.80.2Linuxfabrikmonitoring-pluginsCWE-59Linuxfabrik monitoring-plugins: Symlink following in logfile legacy database …

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-07-29 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.